Skip to content
Penby

Insights

Practical data protection and AI governance guidance for UK organisations. Written from experience, not from research.

All articles

Recent insights

SAR insight guide Guides

What happens when someone asks to see their data

Every organisation the ICO has reprimanded for subject access failures had a SAR policy. The failure is rarely legal; it's operational. Here's what's changed in 2026, what deliberately hasn't, and what a defensible response to a SAR actually looks like.

16 April 2026 Read –
Shadow AI - Penby Feature Guides

You're already using AI – here's what UK law requires

Most boards think their business uses a handful of AI tools. In reality, 71% of employees are using unapproved AI at work. UK GDPR already covers all of it. Here's what the law requires and what to do about it.

13 April 2026 Read –
Data Breach Procedures Guides

Your organisation had a data breach – here's what happens next

The ICO doesn't reward a good breach response. It punishes poor preparation. Here's what actually happens in the first 72 hours, what the enforcement record reveals, and the preparation that genuinely changes the outcome.

11 April 2026 Read –
AI Governance - Where To Start Guides

Building an AI governance framework: where to start

93% of UK organisations use AI. 7% govern it. Most of the governance you need is already required under UK GDPR. The first step isn't a framework document – it's finding out what AI you're actually using.

10 April 2026 Read –
Orrery Sketch - Data Controller and Processor Guides

Sharing data with other organisations: what UK GDPR actually requires

Most organisations focus their data protection effort internally, but the largest unmanaged risk sits in how personal data moves to suppliers, processors, and partners. Only 9% of UK businesses say they transfer data internationally, yet almost all use cloud services that do exactly that.

9 April 2026 Read –
Automated decisions about people Guides

Automated decisions about people: your legal obligations explained

The law on automated decisions about people changed in February 2026 – and the ICO has already found that most organisations' human oversight doesn't meet the new standard. Here's what the framework requires.

8 April 2026 Read –
Why your data protection policies aren't doing what you think they are Analysis

Why your data protection policies aren't doing what you think they are

Most UK organisations have data protection policies on file. But when the ICO investigates, it doesn't ask whether policies exist – it asks whether anyone follows them. Here's how to tell if yours are actually working.

7 April 2026 Read –
Waiting room Analysis

AI bias isn't just an ethics problem – it's a legal one

AI bias creates legal exposure under three UK laws already in force – and the liability sits with the organisation using the tool, not the vendor. Here's what the obligations actually are and what to do about them.

5 April 2026 Read –
The real cost of getting data protection wrong Analysis

The real cost of getting data protection wrong

Many organisations price data protection risk as the risk of an ICO fine. The real cost, operational disruption, civil claims, lost contracts, reputational damage – consistently dwarfs the penalty, and almost every recent case involved basic failures that proactive governance would have caught.

5 April 2026 Read –

Put your data protection in safe hands

Contact us today for a free, no-obligation conversation with a data protection practitioner about your organisation's needs. No sales pitch – just honest, practical advice.

Get in touch